Vendor
high
advisory
Winter CMS Twig Sandbox Escape Vulnerability
2 TTPs 1 CVEAuthenticated backend users with template-editing privileges can bypass the Winter CMS Twig sandbox to execute arbitrary PHP or SQL, stemming from an incomplete fix for CVE-2024-54149.
Winter CMS +1
2t
1c
updated
low
advisory
Stored XSS in Winter CMS and October CMS Backend
1 TTP 2 CVEsAuthenticated backend users can perform stored cross-site scripting (XSS) by injecting malicious content into custom CSS settings in Winter CMS and October CMS.
Winter CMS +2
1t
2c
high
advisory
Improper Input Validation in Winter CMS Backend Postback
1 TTPAuthenticated backend users can exploit an input validation vulnerability in the Winter CMS form postback mechanism to execute restricted controller methods, leading to unauthorized administrative actions.
wn-backend-module
web-application
privilege-escalation
cms
1t